Netoloji Software E-Flow Unrestricted File Upload Vulnerability Allowing Stored Cross-Site Scripting
Vulnerability
A vulnerability in Netoloji Software E-Flow prior to version 3.23.00 allows for unrestricted file uploads of dangerous file types. This issue also involves improper input neutralization during web page generation, leading to cross-site scripting (XSS) vulnerabilities. Additionally, the vulnerability allows access to functionalities not properly constrained by access control lists (ACLs) and enables file content injection.
Impact
Exploitation of this vulnerability could lead to stored cross-site scripting, where injected scripts are executed in the context of the user.
Remediation
Users are advised to update to version 3.23.00 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
